rootpwn

medium · CVSS v3 4.3 · CVSS v4 5.3 · EPSS 0.00271

CVE-2026-96764

kvcache-ai mooncake up to 0.3.12/0.3.14-rc1 contains a resource allocation flaw in MasterService::GetReplicaListByRegex. Remote attackers ca

Overview

kvcache-ai mooncake up to 0.3.12/0.3.14-rc1 contains a resource allocation flaw in MasterService::GetReplicaListByRegex. Remote attackers can trigger excessive memory usage, potentially leading to denial of service. The vulnerability is publicly known and unpatched.

Description

A weakness has been identified in kvcache-ai mooncake up to 0.3.12/0.3.14-rc1. Impacted is the function MasterService::GetReplicaListByRegex of the component Regular Expression Handler. Executing a manipulation can lead to allocation of resources. The attack may be performed from remote. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

Impact

The flaw allows attackers to cause uncontrolled resource consumption, compromising availability. Defenders must monitor memory usage and service responsiveness. The vulnerability does not directly expose data or confidentiality. It primarily threatens the integrity of service uptime.

Remediation

Apply the vendor's patch when released. In the meantime, restrict network access to the MasterService endpoint, limit regex complexity, and enforce rate limiting or resource quotas on the service.

Risk context

Medium severity (CVSS 4.3/5.3) and low EPSS (0.00271) indicate a moderate risk but still actionable. Defenders should prioritize monitoring and apply mitigations promptly.

Affected products

  • kvcache-ai mooncake

Scores

Severity
medium
CVSS v2
4
CVSS v3
4.3
CVSS v4
5.3
EPSS
0.00271

resource-exhaustion regex denial-of-service remote kvcache-ai medium EPSS

← All CVEs